Below is the ground truth of where Habitat OS stands today — what's shipped, what's inherited from our platform partner, and what we're still earning at the TheFocus.AI program level.
Deployment flexibility
Available today Customer VPC, dedicated cloud account, or managed single-tenant on Vercel's enterprise AI Cloud. On-prem deployments supported case-by-case. Your infrastructure team chooses the boundary.
Platform-level certifications
Inherited from Vercel Our managed runtime runs on Vercel's enterprise platform — SOC 2 Type 2, ISO 27001:2022, PCI DSS Level 1, HIPAA-ready (BAA available), and GDPR with DPA. You inherit those controls at the infrastructure layer on day one.
Network isolation
Vercel Secure Compute Managed deployments use dedicated VPC isolation with static egress IPs, private connectivity to your backend systems, and NAT-gateway-controlled outbound traffic. Your allowlists stay short and stable.
Edge protection
Vercel Firewall DDoS mitigation, managed WAF, rate limiting, Attack Challenge Mode, and IP allow/deny rules sit in front of every Habitat endpoint. Configuration changes are logged and instantly reversible.
Data boundary
Always customer-controlled Customer data never leaves customer-controlled storage. Model provider keys can be customer-provided or brokered. Memory, audit logs, and session data persist in storage you own.
Identity & access
Enterprise SSO available SAML / OIDC integration with Okta, Microsoft Entra, and Google Workspace. Role-based access control scoped to Habitat and integration level. Every action is audit-logged with request-level traceability.
Open-source auditability
Public, on GitHub The Habitat engine is Umwelten — published under an OSI-compatible license at github.com/The-Focus-AI/umwelten. Your security team can read every line before deployment.
Principal accountability
Always Every engagement is led by a named principal. Your escalation path goes to the person who built your Habitat, not a support tier.
TheFocus.AI program compliance
SOC 2 Type I in progress Our own SOC 2 Type I audit is underway for 2026. HIPAA BAAs, ISO 27001, and sector-specific programs are evaluated case-by-case. Security posture documentation, deployment diagrams, and data-handling practices available on request under NDA.
Secured on Vercel's AI Cloud
Enterprise controls inherited on day one.
The managed Habitat OS runtime is deployed on Vercel — our enterprise platform partner. Customers running in our managed single-tenant environment inherit Vercel's platform certifications, network isolation, and edge protection at the infrastructure layer. For customer-VPC deployments, the same runtime is delivered into your cloud boundary.
- ✓ SOC 2 Type 2 — Security · Confidentiality · Availability
- ✓ ISO 27001:2022 — Information security management
- ✓ PCI DSS Level 1 — Payment-grade controls at the edge
- ✓ HIPAA-ready — BAA available on Enterprise
- ✓ GDPR + DPA — EU data-handling commitments
- ✓ Secure Compute — Dedicated VPC + static egress IPs
Auditable on GitHub
The engine is open-source.
The Habitat primitives — persona, tools, memory, sub-agents, evals — live in our open-source project, Umwelten. Your security team can read every line, fork it, or run it themselves. Habitat OS is the enterprise distribution: hardened, integrated, supported, accountable.
- ✓OSI-compatible license — no black boxes at the core
- ✓No vendor lock-in — you can run it yourself if we part ways
- ✓Public review — your security team can read before signing